Outlook在中国遭中间人攻击

Analyzer是GreatFire的第一个项目,在2011年上线后,它一如以往的为大家提供测试服务直至今日。现在,我们做了一个新的项目叫做"Blocky",欢迎大家试用这个全新的版本!如果您对此有任何意见和建议,请发送邮件到support@greatfire.org

网络监测组织GreatFire于1月17日收到了报告,指微软电邮系统outlook在中国遭中间人攻击(MITM)。此次攻击针对通过移动设备上的邮件客户端收发outlook邮件的人士。该组织怀疑,此次攻击是审查部门在测试防火墙技术。

当中国用户通过电子邮件客户端(Ice-dove)进入outlook时,可看到以下证书:

Greatfire的测试证实了outlook确实遭到攻击:IMAP(交互邮件访问协议)与SMTP(简单邮件传输协议)都遭受了中间人攻击。但网站界面(https://outlook.com 和 https://login.live.com/)没有受到影响。这次攻击持续了大约一天,现在已经停止。

这种形式的攻击尤其狡猾:相比于通过浏览器,用户通过电子邮件客户端所接收到的警告非常不明显,更容易被忽略。如下图:

(从iphone默认电邮客户端接收到的错误样本)

当客户端试图自动检索信息时,用户只能看见一个突然弹出的警告。因为用户没有主动检索信息,大多数的用户在点击“继续”之前不会细想,却忽视了警告信息、或把警告信息归咎于网络连线的故障。如果用户真的点击了“继续”,他(她)所有的邮件、通讯录、密码都会被黑客所窃取。

这次黑客攻击发生在Gmail被封锁之后的一个月之内(Gmail到现在仍然处于完全无法使用状态)。由于这次中间人攻击与之前对谷歌、苹果、雅虎等的攻击存在诸多相似之处,Greatfire再次怀疑,中国国家互联网信息办公室精心策划了这次袭击,或者有意允许袭击发生。这就意味着中国当局有意进一步打击他们无法容易监控的通信手段

至截稿为止,微软公司尚未对此事作出回应。

三个月前,针对苹果iCloud储存服务的中间人攻击促使苹果总裁库克亲自到中国与当局交涉。中国外交部新闻发言人随后否认了攻击,苹果也从未公开与中方的交涉结果。苹果后来创建了一个“中文帮助页面”来处理相似的问题,并将其称为“有组织的网络攻击”(organized network attacks)。

在苹果被攻击的同时,谷歌和雅虎也有经历类似的中间人攻击,微软outlook的网页版也曾在短时间内受攻击。当局似乎是在测试他们的中间人攻击技术,并搜集用户反应。通过追踪有多少用户忽视了警告信息,当局可以评估这类攻击的有效性。

GreatFire强烈建议用户,千万不要绕过证书提示的“错误信息”去点击“继续”

 

呼吁停止信任CNNIC证书

GreatFire怀疑国家网信办对此次黑客攻击outlook、以及其他几起类似的攻击负有直接责任。由于中国互联网信息中心(CNNIC)的直接主管部门是国家网信办,它所认证的安全证书也因此不值得信任。

GreatFire再次呼吁互联网公司和相关组织,包括微软和苹果,立即停止将CNNIC作为认证机构(certification authority)的信任

- CNNIC的证书有什么作用?

它可以用于初步地识别个人或设备的身份、鉴定服务、加密文件。

什么是认证机构(certification authority: CA)?

认证机构是颁发证书的机构。他们建立和验证了公共密钥的鉴定系统,以及核实请求密钥的个人或组织的身份。

 

Technical Details

IMAP/SMTP are commonly used on mobile email clients (e.g the default mail application on iPhones) and desktop email clients like Thunderbird. Internet Message Access Protocol (IMAP) is a protocol which allows users to connect to the same mailbox through multiple devices (i.e. your desktop, mobile, etc.). Simple Mail Transfer Protocol (SMTP) is typically used by users to send messages to a server which are then relayed to the recipient.

Wikipedia defines a man-in-the-middle (MITM) attack in the following way:

The man-in-the-middle attack...is a form of active eavesdropping in which the attacker makes independent connections with the victims and relays messages between them, making them believe that they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker.

测试

为了在火狐浏览器中复制以上结果,我们首先在火狐中设置允许接入端口993,这也是IMAP所使用的端口。然后,我们登入https://imap-mail.outlook.com:993,立刻收到了警告信息。正如你在下图所看到的那样,这份证书是自我签名的(self-signed)。

  outlook-MITM.png

下图可以看到Chrome中显示的证书错误。Chrome也被设置成允许通过端口993进行连接。

The fake certificate used in the attack:

https://github.com/chengr28/RevokeChinaCerts/blob/master/Windows/Certs/[Fake]AnyHotmailCom_201501.crt

WireCapture:

https://www.cloudshark.org/captures/8bf76336e67d

Reports:

https://www.v2ex.com/t/163062 and https://www.v2ex.com/t/163018.

 

评论

更多博客文章

订阅 email
显示 博客 | Google+ | Twitter | 全部 的消息. 使用 RSS 订阅我们的博客。

星期一, 11月 25, 2024

China’s New Effort to Achieve Cyber Sovereignty

How Real-Name Registration policies create an “ideological firewall” that chills dissent by eliminating user anonymity and selectively restricting transnational access to Chinese social media apps.

星期四, 8月 10, 2023

1.4 million people used FreeBrowser to circumvent the Great Firewall of Turkmenistan

Since 2021, the authorities in Turkmenistan have taken exceptional measures to crack down on the use of circumvention tools. Citizens have been forced to swear on the Koran that they will not use a VPN. Circumvention tool websites have been systematically blocked. Arbitrary searches of mobile devices have also taken place and have even targeted school children and teachers.

The government has also blocked servers hosting VPNs which led to “near complete” internet shutdowns on several occasions in 2022. Current reports indicate that 66 hosting providers, 19 social networks and messaging platforms, and 10 leading content delivery networks (CDNs), are blocked in the country. The government presumably is unconcerned about the negative economic impact that such shutdowns can cause.

星期五, 3月 18, 2022

Well-intentioned decisions have just made it easier for Putin to control the Russian Internet

This article is in large part inspired by a recent article from Meduza (in Russian).

Since the beginning of the war in Ukraine, Russian users have had problems accessing government websites and online banking clients. Browsers began to mark these sites as unsafe and drop the connection. The reason is the revocation of digital security certificates by foreign certificate authorities (either as a direct consequence of sanctions or as an independent, good will move); without them, browsers do not trust sites and “protect” their users from them.

However, these actions, caused - or at least triggered by - a desire to punish Russia for their gruesome actions in Ukraine, will have long-lasting consequences for Russian netizens.

Digital certificates are needed to confirm that the site the user wants to visit is not fraudulent. The certificates contain encryption keys to establish a secure connection between the site and the user. It is very easy to understand whether a page on the Internet is protected by a certificate. One need just look at the address bar of the browser. If the address begins with the https:// prefix, and there is a lock symbol next to the address, the page is protected. By clicking on this lock, you can see the status of the connection, the name of the Certification Authority (CA) that issued the certificate, and its validity period.

There are several dozen commercial and non-commercial organizations in the world that have digital root certificates, but 3/4 of all certificates are issued by only five of the largest companies. Four of them are registered in the USA and one is registered in Belgium.

星期一, 8月 03, 2020

GreatFire 应用生成器 发布

GreatFire (https://en.greatfire.org/) 是一家专注于中国的审查监督组织,我们自豪地宣布一个新的反审查工具,该工具将使任何被屏蔽的媒体、博客、人权组织或民间社会组织反制审查,将其内容得以传播到中国和其他互联网审查国家的数百万读者和支持者的手机上。

GreatFire 已经构建了一个名为“GreatFire 应用生成器”的网页程序,任何组织可以使用它来为中国和其他国家的用户解锁他们的内容。任何人可以访问 (https://appmaker.greatfire.org/),该网站将编译一个带有自己logo的应用,并将包含他们以前被封锁的内容。该应用还将包含一个特殊的、绕过审查的网络浏览器,以便用户可以访问未经审查的网络。这些应用将使用包括机器学习在内的多种策略来规避中国当局先进的审查策略。这个项目在其他有类似中国的审查限制的国家也同样有效。对于组织和最终用户而言,这些应用将免费、快速且非常易于使用。

这个项目的灵感来自于GreatFire自己的应用 自由浏览(https://freebrowser.org/en)的第一手经验,并希望帮助那些可能没有内部专业知识来规避中国审查制度的小型非政府组织。GreatFire的反审查工具在中国发挥了作用,而其他工具却没有。自由浏览可以引导中国的互联网用户从应用的首页进入被僧所内容的导航(http://manyvoices.news/)。

   

人权基金会 (HRF) 已经使用 GreatFire 应用生成器 创建了一个应用程序HRF 在全球范围内促进和保护人权。该组织的使命是确保自由在世界范围内得到维护和促进。 HRF 的网站 在中国被封锁, 但现在中国任何人都可以 下载 HRF Android 应用程序 并访问该网站的信息。

“现在是中国政府防火墙倒塌的时候了,”人权基金会战略顾问王珍妮说。 “与我们在 GreatFire 的朋友一起,我们致力于击败中国的审查制度——在每一部手机。”

GreatFire 应用生成器 的起源可以追溯到 2014 年,当时开放技术基金 (OTF) 支持 GreatFire 的“依附的自由”实验。该项目直接导致了 2015 年中国政府的大规模网络攻击,后来被称为“大炮”。 OTF 还为 GreatFire 开发 AppleCensorship.com,该网站正在跟踪苹果对包括香港在内的全球应用商店的审查情况。

自由浏览 是“大炮”攻击的直接结果,五年后,我们很高兴能够向任何可能遭受中国当局审查的组织提供我们的方法。 

星期五, 7月 24, 2020

Apple, anticompetition, and censorship

On July 20, 2020, GreatFire wrote to all 13 members of the Subcommittee on Antitrust, Commercial and Administrative Law of the U.S. House Committee on the Judiciary, requesting a thorough examination into Apple’s practice of censorship of its App Store, and an investigation into how the company collaborates with the Chinese authorities to maintain its unique position as one of the few foreign tech companies operating profitably in the Chinese digital market.  

This letter was sent a week before Apple CEO TIm Cook will be called for questioning in front of the Subcommittee on Antitrust, Commercial and Administrative Law. The CEOs of Amazon, Google and Facebook will also be questioned on July 27, as part of the Committee’s ongoing investigation into competition in the digital marketplace.

This hearing offers an opportunity to detail to the Subcommittee how Apple uses its closed operating ecosystem to not only abuse its market position but also to deprive certain users, most notably those in China, of their right to download and use apps related to privacy, secure communication, and censorship circumvention.

We hope that U.S. House representatives agree with our view that Apple should not be allowed to do elsewhere what would be considered as unacceptable in the U.S. Chinese citizens are not second class citizens. Private companies such as Apple compromise themselves and their self-proclaimed values of freedom and privacy when they collaborate with the Chinese government and its censors.

使用 RSS 订阅我们的博客。

评论

Removing CNNIC root isn't practical, as it prevents the company from selling devices in China. Please make more practical recommendations. For example, only accept CNNIC-signed certificates for .CN domains. That would allow CNNIC to continue to exercise control over Chinese domains without jeopardizing the security of the entire Internet. (This is basically "TLD pinning" for root CAs.)

 Romantic Getaways: You can also plan a romantic holiday with
your loved one. It is really nice to see all these valentine's
day gift ideas for dogs, cause you two will be hollering with
love don't you know. This need not always be romantic love but any love.

Review my site: Propose Day SMS

After Daytona Beach Police Detectives finished their investigation of the incident, the scene was turned over to a site manager for Clean
Fuels National, who police emphasized was not at the
scene when the incident happened. It has emerged as one of the
best weekend destinations especially for families.
The last four or five years there's been more of a mix of INDYCAR drivers going over, which
is good for both series.

Also visit my web site ... daytona 500 live streaming

this post is awesome, great msg for us, plz update ur blog for daily basis, i am regular visitor of this site, so keep posting for us,

click the below links to create backlink
best free backlink website
click here for msg movie

thanks for this post, keep it up for updating us, i am waiting for ur new article.

thanks again
IPL8 live stream 2015

It’s certainly fresh to writing and seeing concepts which are truly helpful to get the direction

mothers day quotes
happy mothers day qutes 2015
happy mothers day 2015

Nice post to share
http://listacademyanik.com/

Nice post to share.
CLICK HERE>>
http://www.100kfactoryultraeditionreview.com/

----------------------------------------
There many errors that can hurt your PPC project without you even understanding it. For this factor, I wish to present to you the leading 5 factors your Pay Per Click project suffers online. look at part 1 of this article
----------------------------------------
CHECKOUT>>www.100kfactoryultraeditionreview.com

--------------------------------------------------------------------------------
http://listacademyanik.com/
============================================

Hey,

"Good website! I really love how it is easy on my eyes and the data are well written. I am wondering how I could be notified when a new post has been made. I have subscribed to your RSS feed which must do the trick! Have a nice day!"

======================
CLICK HERE>>http://listacademyanik.com/

======================

Hey ,
I would like to thank you for the efforts you have put in writing this website. I'm hoping the same high-grade web site post from you in the upcoming also. In fact your creative writing abilities has inspired me to get my own web site now. Actually the blogging is spreading its wings rapidly.

http://listacademyanik.com/dna-wealth-blueprint-3-0-review-bonus

good Study how to setup Kodi earlier known as noted as XBMC Kodi Download Linux, iOS, Windows, and Android. Moreover, Kodi App Android nice.

good The formal webpage of Droid4x packages a tiny method data file on Droid4x your laptop when you struck the ‘download&' button. nice.

good cannot send or receive messages or pictures utilizing it. snapchat sign in file from its web site and also run the installer as well as nice.

Download caller name announcer from callernameannouncer.uniqsofts.com to read al incoming notifications.

Thanks mate for share this nice post
obat pembesar penis klg: http://obatfrigid.com/obat-klg.html

Playstore in our android devices since long. Though Playstore is fairly aptoide apk you uninstall the app, simply click the apk once again and install

Game Guardian is an amazing game hack/alteration tool. Game guardian helps you modify money, HP, Sp and more aspects of the game.
game guardian apk

I definitely enjoyed every bit of it and I have you bookmarked to see new information on your blog.
my boy

A festival is an event ordinarily celebrated by a community and centering on some characteristic aspect of that community and its religion or traditions. It is often marked as a local or national holiday, mela, or eid.

http://festival-status.wallinside.com

For a lot of us looking to establish an online store, 'e-commerce' is where it all begins. When you find this phrase in articles and testimonials - it simply refers to the buying and selling of products on the internet.
To Get More Info>> https://www.7figurecyclereviewbonus.com/ << VISIT HERE

After reading the article I updated my knowledge regarding the same.
It really helped me a lot.
Thanks for sharing this with us.

https://www.kickstarter.com/profile/netgearsupport/about

At this rate, shouldn't China create their own operating system like what North Korea did? Everything is banned, it's so annoying for tourists. Thank you for sharing the news! I want to visit China some day but with this policy, I can't receive email from work when traveling, it's very hard for me.
https://htmlcolor-codes.com/

添加新评论

Filtered HTML

  • 自动将网址与电子邮件地址转变为链接。
  • 允许的HTML标签:<a> <em> <strong> <cite> <blockquote> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • 自动断行和分段。

Plain text

  • 不允许HTML标记。
  • 自动将网址与电子邮件地址转变为链接。
  • 自动断行和分段。
By submitting this form, you accept the Mollom privacy policy.